CVE-2016-5425
13.10.2016, 14:59
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | tomcat | - |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| tomcat |
| ||
| tomcat-admin-webapps |
| ||
| tomcat-docs-webapp |
| ||
| tomcat-el-2.2-api |
| ||
| tomcat-javadoc |
| ||
| tomcat-jsp-2.2-api |
| ||
| tomcat-jsvc |
| ||
| tomcat-lib |
| ||
| tomcat-servlet-3.0-api |
| ||
| tomcat-webapps |
|
Common Weakness Enumeration
References